Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
262 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.1% | — | Itechscripts Real Estate Script | 16/7/2022 | 17/6/2026 | A vulnerability was found in Itech Real Estate Script 3.12. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /real-estate-script/search_property.php. The manipulation of the argument property_for leads to sql injection. The attack can be launched remotely. The… | |
| Modificada | Crítica (9.3) | 1.4% | — | Realestate Project Realestate | 11/7/2022 | 17/6/2026 | The deepaliupadhyay/RealEstate repository through 2018-11-30 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Media (4.8) | 0.59% | — | Simple Real Estate Pack Project Simple Real Estate Pack | 30/5/2022 | 17/6/2026 | The Simple Real Estate Pack WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed | |
| Modificada | Crítica (9.8) | 1.5% | — | Simple Real Estate Portal System Portal Simple Real Estate Portal System | 21/4/2022 | 17/6/2026 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/admin/?page=agents/manage_agent. | |
| Modificada | Crítica (9.8) | 1.5% | — | Simple Real Estate Portal System Project Simple Real Estate Portal System | 21/4/2022 | 17/6/2026 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Users.php?f=delete_agent. | |
| Modificada | Crítica (9.8) | 1.3% | — | Simple Real Estate Portal System Project Simple Real Estate Portal System | 21/4/2022 | 17/6/2026 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_estate. | |
| Modificada | Crítica (9.8) | 1.3% | — | Simple Real Estate Portal System Project Simple Real Estate Portal System | 21/4/2022 | 17/6/2026 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_type. | |
| Modificada | Crítica (9.8) | 1.2% | — | Simple Real Estate Portal System Project Simple Real Estate Portal System | 21/4/2022 | 17/6/2026 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_amenity. | |
| Modificada | Crítica (9.8) | 1.2% | — | Simple Real Estate Portal System Project Simple Real Estate Portal System | 2/3/2022 | 17/6/2026 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter. | |
| Modificada | Media (6.1) | 3.7% | 💥 Exploit | Contempothemes Real Estate 7 | 6/7/2021 | 17/6/2026 | The WP Pro Real Estate 7 WordPress theme before 3.1.1 did not properly sanitise the ct_community parameter in its search listing page before outputting it back in it, leading to a reflected Cross-Site Scripting which can be triggered in both unauthenticated or authenticated user context | |
| Modificada | Alta (8.8) | 0.82% | — | Realestateconnected Easy Property Listings | 18/2/2020 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Easy Property Listings versions prior to 3.4 allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modificada | Alta (7.2) | 1.0% | — | Advanced Real Estate Script Project Advanced Real Estate Script | 5/1/2020 | 17/6/2026 | In PHP Scripts Mall advanced-real-estate-script 4.0.9, the news_edit.php news_id parameter is vulnerable to SQL Injection. | |
| Modificada | Media (6.1) | 0.70% | — | Advanced Real Estate Script Project Advanced Real Estate Script | 5/1/2020 | 17/6/2026 | In PHP Scripts Mall advanced-real-estate-script 4.0.9, the search-results.php searchtext parameter is vulnerable to XSS. | |
| Modificada | Media (6.1) | 1.00% | — | Realestateconnected Easy Property Listings | 30/8/2019 | 17/6/2026 | The easy-property-listings plugin before 3.4 for WordPress has XSS. | |
| Modificada | Media (5.3) | 1.5% | — | Open Source Real-estate Script Project Open Source Real-estate Script | 4/10/2018 | 17/6/2026 | PHP Scripts Mall Open Source Real-estate Script 3.6.2 allows remote attackers to list the wp-content/themes/template_dp_dec2015/img directory. | |
| Modificada | Media (5.4) | 0.55% | — | Advanced Real Estate Script Project Advanced Real Estate Script | 10/8/2018 | 17/6/2026 | PHP Scripts Mall advanced-real-estate-script has XSS via the Name field of a profile. | |
| Modificada | Media (6.5) | 0.94% | — | Advanced Real Estate Script Project Advanced Real Estate Script | 10/8/2018 | 17/6/2026 | PHP Scripts Mall advanced-real-estate-script 4.0.9 allows remote attackers to cause a denial of service (page structure loss) via crafted JavaScript code in the Name field of a profile. | |
| Modificada | Alta (8) | 0.45% | — | Advanced Real Estate Script Project Advanced Real Estate Script | 10/8/2018 | 17/6/2026 | PHP Scripts Mall advanced-real-estate-script 4.0.9 has CSRF via edit-profile.php. | |
| Modificada | Alta (7.5) | 1.0% | — | Csa-estate Csatoken | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for CSAToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Crítica (9.8) | 2.0% | 💥 Exploit | OS Property Real Estate Project OS Property Real Estate | 22/2/2018 | 17/6/2026 | SQL Injection exists in the OS Property Real Estate 3.12.7 component for Joomla! via the cooling_system1, heating_system1, or laundry parameter. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Comdev Jomestate PRO | 17/2/2018 | 17/6/2026 | SQL Injection exists in the JomEstate PRO through 3.7 component for Joomla! via the id parameter in a task=detailed action. | |
| Modificada | Media (5.4) | 0.54% | — | Multilanguage Real Estate MLM Script Project Multilanguage Real Estate MLM Script | 7/2/2018 | 17/6/2026 | PHP Scripts Mall Multilanguage Real Estate MLM Script 3.0 has Stored XSS via every profile input field. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Multilanguage Real Estate MLM Script Project Multilanguage Real Estate MLM Script | 29/1/2018 | 17/6/2026 | SQL Injection exists in Multilanguage Real Estate MLM Script through 3.0 via the /product-list.php srch parameter. | |
| Modificada | Media (4.8) | 0.49% | — | Advanced Real Estate Script Project Advanced Real Estate Script | 3/1/2018 | 17/6/2026 | Online Ticket Booking has XSS via the admin/eventlist.php cast parameter. | |
| Modificada | Media (4.8) | 0.49% | — | Advanced Real Estate Script Project Advanced Real Estate Script | 3/1/2018 | 17/6/2026 | Online Ticket Booking has XSS via the admin/movieedit.php moviename parameter. |